Back to Directory/Developer Tools

io.github.dockndevai/mcp-macos

Observe & operate a Mac — files, processes, apps, shell, AppleScript, GUI — safe by default.

Developer ToolsTypeScriptv0.2.0

mcp-macos

npm CI licence

A safe-by-default Model Context Protocol server that lets an agent observe and operate a Mac — read files, list processes and apps, take screenshots (read-only); write files, set the clipboard, post notifications, open things (read-write); and, behind explicit opt-ins, run commands / AppleScript, delete to Trash, kill processes and drive the GUI (admin).

It starts read-only. Every high-impact power needs both admin mode and its own flag, and the most dangerous ones ask the human to approve each call. Part of the dockndevai MCP server suite — one governance model across all of them.

Pure Node + osascript/screencapture — no native add-ons. macOS only.

What it gives an agent

The server starts read-only (see Safe by default); higher-capability tools are only registered when you raise the mode.

ToolForNeeds mode
system_infomacOS version, hardware, memory, load, uptimeread-only
list_directory / read_filebrowse & read files (path-allowlisted)read-only
list_processesrunning processes by CPU/memread-only
get_clipboardread the clipboardread-only
list_apps / get_frontmost_apprunning apps; the active oneread-only
screenshotcapture the screen as a PNGread-only
write_filecreate/overwrite a file (confirms on overwrite)read-write
set_clipboard / notify / openset clipboard, notify, open a file/URL/appread-write
run_commandrun a program (argv, no shell)admin + MACOS_ALLOW_EXEC
run_applescriptrun AppleScript / JXAadmin + MACOS_ALLOW_EXEC
kill_processsignal a processadmin + MACOS_ALLOW_EXEC
delete_pathmove a path to the Trashadmin + MACOS_ALLOW_DELETE
type_text / key_press / click / move_mousedrive the GUIadmin + MACOS_ALLOW_INPUT

Install

npx -y @dockndevai/mcp-macos

Requires macOS and Node ≥ 22. click/move_mouse also need cliclick (brew install cliclick).

Configure

{
  "mcpServers": {
    "macos": {
      "command": "npx",
      "args": ["-y", "@dockndevai/mcp-macos"],
      "env": {
        "MACOS_MODE": "read-only"
      }
    }
  }
}

See docs/CLIENTS.md for Claude Code / Cursor / Codex / VS Code / Windsurf snippets, and .env.example for every supported variable.

Safe by default

This server can drive an entire Mac, so the access model (enforced by src/security.ts) is deliberately strict — defence in depth, not documentation:

QuestionSettingDefaultNotes
What can it do at all?MACOS_MODEread-onlyread-only observes; read-write writes files/clipboard/opens; admin adds exec/delete/kill/GUI. Tools above the mode are never registered.
Which paths can it touch?MACOS_PATH_ALLOWLIST(anywhere)Comma-separated roots. When set, any file op outside them is refused.
Which paths are read-only forever?MACOS_PROTECTED_PATHSsystem + secrets/System, /usr, /bin, /sbin, /private, /Library, ~/.ssh, ~/.aws, ~/.gnupg, ~/Library/Keychains — readable, never mutated.
Can it run commands?MACOS_ALLOW_EXECfalseGates run_command, run_applescript, kill_process (on top of admin).
Restrict which programs?MACOS_COMMAND_ALLOWLIST(any)When set, run_command may only invoke these program names.
Can it delete?MACOS_ALLOW_DELETEfalseGates delete_path (moves to the Trash, recoverable).
Can it drive the GUI?MACOS_ALLOW_INPUTfalseGates type_text/key_press/click/move_mouse.
Preview without doingMACOS_DRY_RUNfalseMutating tools validate + log intent, then return.
Audit trailMACOS_AUDIT_LOGtrueJSON line to stderr per guarded operation (ALLOW/DENY/DRY_RUN).
Interactive confirmation(automatic)—run_command, run_applescript, delete_path, kill_process and file overwrites ask the human to approve via MCP elicitation before running; clients without elicitation fall back to the flags.

See SECURITY.md.

macOS permissions

The host process (your terminal / MCP client) must be granted, in System Settings → Privacy & Security:

  • Screen Recording — for screenshot.
  • Accessibility — for type_text / key_press / click / move_mouse.
  • Automation (per-app prompts) — for run_applescript and app control.
  • Files and Folders / Full Disk Access — to read/write outside the default sandbox.

You'll be prompted the first time each is needed; nothing works around a permission you haven't granted.

Developing

npm install
npm run build
MACOS_MODE=read-only node dist/index.js
# introspect the tool list:
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | node dist/index.js

Licence

MIT

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y @dockndevai/mcp-macos

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-dockndevai-mcp-macos": {
      "command": "npx",
      "args": [
        "-y",
        "@dockndevai/mcp-macos"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

@dockndevai/mcp-macosnpm

Compatible MCP Clients

io.github.dockndevai/mcp-macos works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More